Security Incident Response Analyst

Posted 13 hours ago

This is a fully remote position, open to applicants in North Carolina, +1 more state.

📋 Description

• Oversee high-severity investigations across endpoint, identity, email, network, cloud, and SaaS telemetry.

• Construct and support incident timelines while identifying root causes.

• Implement containment measures which include session revocation, credential resets, token invalidation, host isolation, mailbox rule removals, conditional access modifications, and network blocks.

• Conduct eradication and recovery processes, confirm adversary removal, and eliminate persistence strategies.

• Execute log analysis and basic forensics across memory, disk, M365/Entra audit logs, and proxy/firewall/VPN logs.

• Safeguard evidence for legal and regulatory assessment.

• Direct investigations involving PHI/PII related to unauthorized access, data exposure, insider misuse, compromised devices, and third-party vulnerabilities.

• Assess data involvement, access, duration, viewing, and exfiltration; document outcomes for HIPAA breach risk assessments.

• Collaborate with Privacy, Compliance, and Legal teams regarding breach determinations and notifications.

• Oversee the takedown or remediation of exposed data.

• Contribute to DLP, access evaluations, data classification, and secure file-transfer protocols.

• Manage incident communications directed to the CISO, security leadership, business stakeholders, IT, Legal, Privacy, and HR.

• Produce incident reports and conduct post-incident evaluations.

• Coordinate with MDR/MSSP, forensic retainers, cyber insurance providers, vendors, and external partners.

• Adjust and develop SIEM detections and response playbooks.

• Evaluate and decrease false positives, dwell time, and response duration.

• Execute proactive threat hunts and translate findings into detections or fortification suggestions.

• Identify control deficiencies and drive remediation efforts with responsible teams.

• Mentor and assess L1/L2 analyst investigations.

• Maintain runbooks, severity definitions, and escalation protocols.

• Participate in the on-call rotation and facilitate tabletop exercises.


⛳️ Requirements

• Minimum of 5 years in security operations or incident response.

• At least 2 years of experience independently leading investigations on high-severity incidents.

• Extensive, practical knowledge in SIEM and detection engineering.

• Proficiency in query languages such as KQL, SPL, or equivalent.

• Experience with correlation logic, detection tuning, and onboarding log sources.

• Familiarity with Microsoft Sentinel, Rapid7 InsightIDR, Splunk, or similar SIEM tools.

• Expertise in Microsoft Entra ID / Active Directory, Conditional Access, MFA, OAuth/consent grants, token and session abuse, privileged access, and offboarding controls.

• Proficient in BEC and phishing investigations, including header/URL/attachment analysis, mail-flow rules, DMARC/DKIM/SPF, secure email gateways, and API-based email security tools.

• Experience in EDR investigation and response, including Defender for Endpoint, CrowdStrike, or similar platforms.

• Knowledge of endpoint persistence and lateral movement tactics.

• Background in analyzing logs from firewalls, proxies, VPNs, and DNS.

• Understanding of network segmentation, C2 patterns, and data exfiltration indicators.

• Familiarity with MITRE ATT&CK framework.

• Strong written communication skills.

• Experience investigating incidents involving PHI/PII or other regulated data, including data exposure scoping and support for breach risk assessments.

• Preferred experience in the healthcare sector and knowledge of HIPAA Privacy/Security Rules, breach notification requirements, and state privacy regulations.

• Cloud incident response experience is a plus.

• Proficiency in scripting languages such as PowerShell, Python, or KQL is preferred.

• Experience with SOAR platforms is advantageous.

• Certifications such as GCIH, GCFA, GCIA, CISSP, or Microsoft SC-200 are preferred.

• Experience managing incidents involving third parties, vendors, or divested/carved-out business units is preferred.


🏝️ Benefits

• Coverage for medical, dental, and vision care.

• Paid time off plan.

• 401(k) plan.

• Flexible spending accounts.

• Basic life insurance.

• Short-term and long-term disability coverage.

• Accident insurance.

• Teammate assistance program.

• Paid parental leave.

• Domestic partner benefits.

• Programs focused on mental, physical, and financial well-being.

People also viewed

Live Nation Entertainment8 hours ago

Senior Director – Cyber Security Operations

US flagCalifornia, +2 more statesFull-timeSecurity Operations$188k – $235k/year
ApplyView job
Samsara9 hours ago

Senior Security Operations Engineer

US flagUnited States, +2 more locationsFull-timeSecurity Operations$135.5k – $227.7k/year
ApplyView job
Axians Somnitec AG2 days ago

Security Operations Engineer – Microsoft Solutions

CH flagSwitzerland OnlyFull-timeSecurity Operations
ApplyView job
Axians2 days ago

Security Operations Engineer – Microsoft Solutions

CH flagSwitzerland OnlyFull-timeSecurity Operations
ApplyView job
Axians Somnitec AG2 days ago

Security Operations Engineer – Microsoft Solutions

CH flagSwitzerland OnlyFull-timeSecurity Operations
ApplyView job
Vi2 days ago

Security Operations Engineer – Microsoft Solutions

CH flagSwitzerland OnlyFull-timeSecurity Operations
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers